VDB

CVE-2018-1075

CVE-2018-1075 PUBLISHED CVSS 5 MEDIUM

ovirt-engine up to version 4.2.3 is vulnerable to an unfiltered password when choosing manual db provisioning. When engine-setup was run and one chooses to provision the database manually or connect to a remote database, the password input was logged in cleartext during the verification step. Sharing the provisioning log might inadvertently leak database passwords.

EPSS 0.39% · 32.2th percentile

Risk Scores

CVSS 3.0
5
CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N
EPSS Score
0.39%
32.2th percentile

Affected Products

VendorProductVersions
ovirtovirt0
[UNKNOWN]ovirt-engineup to ovirt-engine 4.2.3

Timeline

  • Jun 12, 2018 CVE Published
  • Apr 14, 2021 EPSS Score
  • Jun 23, 2021 EPSS Score
  • Aug 24, 2021 EPSS Score
  • Oct 26, 2021 EPSS Score
  • Dec 28, 2021 EPSS Score
  • Feb 28, 2022 EPSS Score
  • May 2, 2022 EPSS Score
  • May 13, 2022 CVE Updated
  • Jul 4, 2022 EPSS Score
  • Sep 5, 2022 EPSS Score
  • Nov 7, 2022 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›